arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.23854cs.NI

BotScan:一种用于大规模识别活跃物联网僵尸网络C2服务器的自适应主动探测方法

BotScan: An adaptive active probing approach for identifying live IoT Botnet C2 servers at scale

S M Maksudul Alam, Vivek Jain, Zhaowei Tan, Srikanth V. Krishnamurthy, Michalis Faloutsos

首次发表
浏览论文内容

中文总结 AI 辅助

该研究提出BotScan方法,通过利用物联网僵尸网络通信协议特性与C2服务器空间局部性,高效探测IP空间,找到的活跃C2服务器数量约为基线的两倍,还识别出896台含112台未报道的C2服务器。

中文摘要 AI 辅助

如何主动搜索并大规模识别僵尸网络的活跃C2服务器?可扩展性要求促使我们在计算资源和探测数据包数量方面高效利用资源。我们提出BotScan,这是一种主动探测大规模IP空间以寻找尽可能多活跃C2服务器的方法。BotScan的新颖之处在于两个通过经验确立的见解:首先,与流行的以个人电脑为中心的观察结果相反,我们在六个主要家族中观察到,许多现代物联网僵尸网络通信协议使用定制程度极低的数据包;其次,C2服务器表现出可利用的行为模式,例如强空间局部性。我们通过开发一种简化方法来证实第一个见解:给定恶意软件二进制文件,我们测量并分类其C2通信协议的“可重放性”。然后,我们引入一种行为自适应探测策略,该策略:(a)使用两级以网段为中心的方法利用C2服务器的空间局部性,(b)根据探测成功情况动态调整。我们使用1842个近期收集的物联网恶意软件二进制文件验证我们方法的有效性,并探索250万个IP地址的目标空间。首先,基于重放的方法适用于至少72%的恶意软件二进制文件;其次,在相同探测数量下,我们的方法找到的活跃C2服务器数量约为基线方法的两倍。我们还开展了两个案例研究,识别出896台活跃服务器,其中包括112台未被报道的C2服务器。

英文摘要

How can we actively search and identify live C2 servers of botnets at scale? The scalability requirement introduces the need to utilize resources efficiently in terms of computation and number of probing packets. We propose BotScan, an approach for actively probing a large IP space to find the highest possible number of live C2 servers. The novelty of BotScan revolves around two insights, which we establish empirically. First, contrary to popular PC-centric observations, many modern IoT botnet communication protocols use packets with minimal customization, which we observe across six major families. Second, C2 servers exhibit exploitable behavioral patterns, such as strong spatial locality. We substantiate the first insight by developing a streamlined approach where, given malware binaries, we measure and taxonomize the "replayability" of its C2 communication protocol. Then, we introduce a behavior-adaptive probing strategy that: (a) exploits the spatial locality of C2 servers using a two-level segment-centric approach, and (b) adapts dynamically to the success of its probes. We validate the effectiveness of our method using 1,842 recently collected IoT binaries, and we explore a target space of 2.5M IP addresses. First, a replay-based method is applicable for at least 72% of the malware binaries. Second, our method outperforms baseline methods by finding approximately double the live C2 servers for the same number of probes. We also conduct two case-studies where we identify 896 live servers including 112 unreported C2 servers.

↑